Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / How To's / What Is Cloudflare, and Did It Really Leak My Data All Over the Internet?

What Is Cloudflare, and Did It Really Leak My Data All Over the Internet?

Latest Govt. Jobs 16:42:00 How To's Edit
Over the past few months, a bug in the popular Cloudflare service may have exposed sensitive user data—including usernames, passwords, and private messages—to the world in plain text. But how big is this problem, and what should you do?

What Is Cloudflare?

Cloudflare is a service that offers security and performance features (among other things) to a wide network of websites. It acts as a reverse proxy, a middleman between you—the user—and a given website. When you go to visit that site, you’ll be directed to one of Cloudflare’s servers instead of the actual site’s servers.
This allows Cloudflare to ensure you’re a legitimate user (thus protecting against denial of service attacks), load the site faster (since they’ve cached certain parts of the site), and protect against downtime (since they have multiple servers worldwide and can fall back on any server if one has a problem).
Cloudflare ensures DDoS attackers don’t get their traffic through to the actual website.
In short: Cloudflare aims to make sites faster and more secure, and it’s a service a lot of websites use.

What Happened? (And What Is “Cloudbleed?”)

Unfortunately, nothing is 100% secure, even if a site uses a service like Cloudflare, and bugs happen. In this case, Cloudflare actually caused a security problem: a bug in the reverse proxy code that parses HTML caused Cloudflare’s servers to leak the contents of its memory in certain circumstances. (Some people are referring to this as “Cloudbleed”, a play off the Heartbleed bug that also affected a large portion of the internet.)
This data could have included all kinds of sensitive data, including usernames, passwords, private messages, OAuth tokens, and a lot more. Even worse, some of that data was indexed and cached by some search engines (about 700 pages, according to Cloudflare), so if you knew what to search on Google, you could find sensitive data from users logging in at the time of a specific leak.
If you know what to search, you could find some of Cloudflare’s leaked information on search engines.
This bug went undiscovered for about five months, and was patched after being discovered this week. Cloudflare says “the greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests).”
But with a service as popular as Cloudflare, 0.00003% is still a lot. Some folks have been compiling a list of sites that use Cloudflare, and it includes over 4 million domains—including Yelp, OkCupid, Uber, Authy, Medium, and many many more. (Some mobile apps are affected as well.)
You can read more about the technical details of this bug at Cloudflare’s blog, though it will probably only interest you if you’re a programmer—if you’re a regular internet user, the only thing you need to know is…

What Should I Do?

First: don’t panic too much. Not every site on that list of 4 million necessarily leaked sensitive information—if a site was just using Cloudflare to cache image data, for example, there would be no sensitive information to leak. And it’s not like each leak was a master list of passwords anyway—it was random pieces of information, which could have included a few random usernames and passwords at any given time.
However, Cloudflare also noted that one of their own private keys was leaked, which would have provided an attacker access to a lot of internal Cloudflare data—including, potentially, usernames and passwords.  Cloudflare was extremely vague about this particular point, despite it being a major security risk with the potential to leak a lot more sensitive information
All that said, there’s no real way to tell if any of your data was leaked and where, so the only safe course of action right now is to change all of your passwords. (Sure, you could look through the list of 4 million sites and only change those used by Cloudflare, but honestly, it’d probably be easier and faster to just change them all.)
The usual rules with passwords apply here: don’t use the same password on multiple sites, use a password manager like LastPass, and turn on two-factor authentication for every site that allows it. If you aren’t doing these things, the Cloudflare bug is probably the least of your worries—after all, sites get hacked all the time, and if you’re using the same password everywhere, all your data is regularly at risk.
If you’re already using a password manager, this process should be easy (if a bit long and boring). But you should be used to this dance by now.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


How to get BookMyShow Instant Disco...

How To Get Free Recharge And Money ...

How to Sync Your Contacts Between A...
What Is Cloudflare, and Did It Really Leak My Data All Over the Internet? What Is Cloudflare, and Did It Really Leak My Data All Over the Internet? Reviewed by Latest Govt. Jobs on 16:42:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • Sony RX100 (2017) review
    Sony RX100 (2017) review
    02.03.2017 - 0 Comments
    Sony PROS: Sleek Great screen Shoots in raw format Customisable buttons Picture…
  • Razer’s ‘Project Linda’ turns your smartphone into a laptop
    Razer’s ‘Project Linda’ turns your smartphone into a laptop
    18.01.2018 - 0 Comments
    Razer’s Project Linda laptop dock concept is one of the most interesting devices to be showcased at CES this…
  • MagicX App – Get 10% Cashback On Bills Payment Of Rs 150 [All Users] www.ultimateztricks.com
    MagicX App – Get 10% Cashback On Bills Payment Of Rs 150 [All Users] www.ultimateztricks.com
    11.03.2016 - 0 Comments
    Magicx app is offering 10% cashback on bills payment of Rs 150 or more. This is an amazing offer. You can get…
  • AOC’s curved frameless Agon monitors push gaming immersion to the max
    AOC’s curved frameless Agon monitors push gaming immersion to the max
    21.02.2017 - 0 Comments
    AOC has revealed a pair of new curved gaming monitors which benefit from a…
  • How to customize Windows 10 colors
    How to customize Windows 10 colors
    12.02.2017 - 0 Comments
    Denise wanted to know why she couldn’t adjust the colors of her windows in Windows 10 like she could in…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Fitbit Zip 2017 review
    Fitbit PROS ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...

Random Posts

  • Reliance says Jio actions 110 crore GB statistics each month, is now biggest in the global
    Reliance says Jio actions 110 crore GB statistics each month, is now biggest in the global
    26.04.2017 - 0 Comments
    Over 7 months after it was publicly rolled out, Jio has become the world's biggest wireless network in…
  • New Android 7.1.2 beta 2 for Pixel C provides Pixel launcher, present day multitasking interface
    New Android 7.1.2 beta 2 for Pixel C provides Pixel launcher, present day multitasking interface
    23.03.2017 - 0 Comments
    A great sign of cohesion for the old Pixel C getting with the times. Android 7.1.2 beta 2 has started…
  • iPhone 8 can make Apple world’s first trillion dollar company
    iPhone 8 can make Apple world’s first trillion dollar company
    19.08.2017 - 0 Comments
    Aiding on the ‘better-than-expected iPad and iPhone sales’, the upcoming flagship device iPhone 8could…
  • Nikon D5300 (2017) review
    Nikon D5300 (2017) review
    02.03.2017 - 0 Comments
    Nikon VERDICT A 24-million-pixel SLR with a 3.2-inch articulating screen, 39-point AF system and Wi-Fi…
  • UPCOMING MOBILES (HUAWEI MATE 9 PORSCHE DESIGN)
    UPCOMING MOBILES (HUAWEI MATE 9 PORSCHE DESIGN)
    09.11.2016 - 0 Comments
    SUMMARY The Huawei Mate 9 Porsche Design mobile features a display and has 4000 mAh battery…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!